Jobs · Information Technology · New York

Director, App Security

TKO · New York, NY · 1 mo ago
Information Technology$143k/yrFull-time

About the Role

We are looking for a hands-on Director, Application Security Engineering to strengthen our cybersecurity posture and partner directly with teams building software across web, mobile, data, and AI-enabled workflows. This role will embed security into delivery practices, improve how we prevent and remediate risk, and communicate clearly with both technical and non-technical stakeholders. This is a hybrid role (3 days/week in-office) with preference given to candidates near a TKO office, including NYC, Stamford, Orlando, Austin, or Las Vegas.

Responsibilities

  • Own and evolve application security practices across the SSDLC, emphasizing scalable, developer-aligned, shift-left controls
  • Operate and improve SAST, SCA, secret scanning, code scanning, repository protections, and related controls across repositories and CI/CD pipelines
  • Develop secure development enablement for citizen developers, vibe coding, and AI-assisted development, including practical guidance for tooling, code assurance, identity, observability, and enterprise standards
  • Review application and code-level vulnerabilities, validate findings, reduce noise, and drive risk-based remediation plans
  • Conduct threat modeling and security design reviews for new systems, major changes, integrations, APIs, and high-risk workflows
  • Advise teams on secure coding, authentication and authorization, session management, secrets handling, logging, encryption, dependency hygiene, and data protection
  • Improve security guardrails for build pipelines, containers, APIs, third-party components, and deployment practices across modern and legacy environments
  • Mature risk-based vulnerability management across intake, validation, prioritization, remediation guidance, exception handling, and reporting
  • Support secure adoption of AI-assisted development and agentic systems by assessing trust boundaries, data exposure paths, prompt and tool-invocation risks, and misuse scenarios
  • Develop pragmatic standards, playbooks, reference architectures, documentation, and office-hour support that improve consistency without slowing teams down unnecessarily
  • Track recurring weaknesses, recommend structural fixes, and help leadership understand where engineering investment will reduce risk most effectively
  • Use AI productively and responsibly to accelerate analysis, triage, documentation, coding support, and security review while maintaining strong human judgment

What Good Looks Like

  • Engineering teams get faster, clearer, and more actionable security guidance as well as assistance with implementation and mechanics for a "teach a person to fish" approach
  • Security tooling produces more trustworthy signals and leads to better adoption, not just more alerts
  • Teams catch and remediate issues earlier in design and development rather than late in release cycles
  • Application and agent-security risks are surfaced in practical terms with concrete mitigation paths
  • Standards, playbooks, and tooling make secure delivery easier and more consistent
  • Security becomes more embedded in day-to-day engineering execution and technical operations, and less dependent on last-minute security scrambles and efforts

Requirements

  • 5+ years of hands-on experience in application security, product security, DevSecOps, and security engineering or a closely related software security role
  • Proven experience working directly with engineering teams in fast-moving delivery environments
  • Hands-on experience configuring, tuning, and operationalizing SAST, SCA, and related tooling such as SonarQube, Dependabot, GitHub, GitHub Advanced Security, or comparable platforms
  • Ability to interpret and reason about code, identify meaningful risk, and provide specific, implementable remediation guidance to engineers
  • Practical experience with SSDLC and shift-left practices, including automated code review support, threat modeling, security design review, and vulnerability management
  • Strong understanding of application and API security, including common software weaknesses, authN/authZ, secrets handling, dependency risk, injection, deserialization, and data protection
  • Experience integrating reliable, scalable, and minimally disruptive security controls into CI/CD pipelines and developer workflows
  • Hands-on familiarity with cloud and modern software delivery patterns, including containers, IaC, and Git-based workflows
  • Strong judgment in vulnerability triage, balancing severity, exploitability, business impact, and engineering realities
  • Ability to write clear guidance, standards, and technical documentation for technical and non-technical audiences
  • Bias toward automation, simplification, and scalable solutions over manual heroics
  • Broad DevSecOps mindset across code, pipelines, dependencies, platforms, deployment, and operations
  • Experience using AI tools responsibly to improve engineering and security outcomes

Preferred Qualifications

  • Experience securing AI agents, LLM-enabled applications, copilots, or agentic workflows in production or near-production environments
  • Experience with DAST, API security testing, penetration testing coordination, red-team support, or adversarial testing of application and AI systems
  • Experience with policy-as-code, IaC scanning, container/image security, software supply-chain security, SBOMs, provenance, attestation, and secrets management
  • Familiarity with cloud security across AWS and/or GCP and the application-layer implications of cloud-native architectures
  • Experience in regulated, audit-sensitive, or event-critical environments where evidence, controls, and operational rigor matter
  • Experience building metrics, dashboards, or reporting that show AppSec posture and remediation progress
  • Experience mentoring engineers and influencing secure engineering culture without direct people management responsibility

Pay

Hiring rate range: $142,500 – $190,000 annually (minimum will not fall below the applicable State/local minimum salary thresholds).

Schedule

Hybrid role requiring 3 days per week in-office.

Similar jobs

Director, App Security

Ultimate Fighting ChampionshipNew York, NY· 1 mo ago
Information Technology$143k/yrapply on teamworkonline.com

Director, App Security

WWENew York, NY· 1 mo ago
Information Technology$143k/yrapply on wwecorp.wd5.myworkdayjobs.com